CVE-2025-3804: thautwarm vscode-diana Jinja2 Template Gen.py injection
Published Apr 19, 2025
·Updated
A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
thautwarm vscode-diana
Event History
Apr 19, 2025
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Aug 5, 57285
Event
via FIRST·03:39 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-3804?
CVE-2025-3804 is classified as a critical vulnerability.
2
How do I fix CVE-2025-3804?
To fix CVE-2025-3804, ensure that you update the thautwarm vscode-diana to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2025-3804?
CVE-2025-3804 is an injection vulnerability related to the Jinja2 Template Handler.
4
Who is affected by CVE-2025-3804?
CVE-2025-3804 affects users of thautwarm vscode-diana version 0.0.1.
5
Is local access required for CVE-2025-3804 exploitation?
Yes, attacking locally is a requirement for exploiting CVE-2025-3804.